
What the document says
Regulation (EU) 2016/679, the General Data Protection Regulation, was adopted on 27 April 2016 and became directly applicable across the European Union from 25 May 2018, according to the regulation's own text published in the Official Journal. The regulation makes appropriate security of personal data a direct legal obligation on organisations that process it, rather than a matter left to contract or industry practice, and backs that obligation with the possibility of administrative fines. It also creates a breach-notification duty: a controller that experiences a personal data breach must notify its supervisory authority, and in defined cases the affected individuals, within a set window measured in hours rather than the weeks or months some organisations had previously taken.
The regulation leaves substantial interpretive work to national supervisory authorities. The UK Information Commissioner's Office guidance, reflecting the document as currently published, states that notification is required without undue delay, but not later than 72 hours after becoming aware of a qualifying breach, that organisations must justify any delay beyond that window, and that whether a breach is serious enough to require notification requires case-by-case assessment. The ICO's own guidance states that failing to notify can itself draw a fine of up to £8.7 million or 2 per cent of global turnover, separate from any fine for the breach itself.
Confidence and limits
The regulation's adoption and application dates, and its basic structure, come directly from the Official Journal text. This article describes UK regulatory guidance current at the time of writing rather than every EU member state's supervisory authority; other authorities interpret the same 72-hour requirement and issue their own guidance, and figures such as the ICO's stated fine ceiling reflect UK domestic legislation implementing the regulation rather than the EU-wide text itself.
Why it mattered
Before the regulation applied, breach notification across Europe was inconsistent: some sectors and countries required it, many did not, and there was no common clock. Making the security of personal data a direct legal duty, rather than a matter inferred from contract or consumer-protection law, changed how organisations budgeted for security and how quickly incidents had to be escalated internally, since a 72-hour external deadline requires an internal detection-to-decision process considerably faster than that.
Defensive takeaway
Confirm that your organisation's incident-response process can realistically determine, staff and document a breach-notification decision inside 72 hours of detection, not just of confirmation, since the clock in most interpretations starts at awareness.
- Could your organisation reach a documented, defensible breach-notification decision within 72 hours of first detecting an incident?
- Do you know which supervisory authority you would need to notify, and in what format, before an incident occurs?
- Is your case-by-case risk assessment for notification decisions documented well enough to justify later, if a regulator asks?
The regulation's most cited feature, the 72-hour clock, is simple to state and considerably harder to operationalise, since it depends on an organisation's ability to detect and assess a breach quickly, and the regulation itself leaves the harder judgment calls about severity and notification to supervisory authorities and to the organisations they oversee.
Confirm that your organisation's incident-response process can realistically determine, staff and document a breach-notification decision inside 72 hours of detection, not just of confirmation, since the clock in most interpretations starts at awareness.
The regulation's adoption and application dates and its basic structure come directly from the Official Journal text; the cited fine figures and interpretive detail come from UK domestic regulatory guidance rather than every EU supervisory authority, and other authorities may state figures differently under their own national legislation.
Sources & reading trail
Confirms the regulation's official title, adoption on 27 April 2016, and application from 25 May 2018.
government-primary · Source published: 27 April 2016 · Retrieved: 16 September 2026
UK regulator's guidance on the 72-hour notification clock, the case-by-case risk assessment, and the penalty for failing to notify.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.